Gemalto CEO: HCE Not Secure for EMV Payments Unless Tokens Stored on Secure Elements or TEE

France-based vendor Gemalto Thursday confirmed its growth projections for 2014 and its longer-term forecast for 2017, despite the recent announcements of support for host-card emulation by Visa and MasterCard Worldwide.

Gemalto, the world’s largest smart card supplier and also the largest trusted service manager, has much to lose if pure host-card emulation, or HCE, takes off. It would enable banks and other service providers to avoid putting their applications on NFC SIMs, like the ones Gemalto supplies by the millions to mobile operators; or to require the hiring of a TSM to manage those applets over the air on the SIMs or other secure elements. 

Gemalto CEO Olivier Piou, while he questioned the inherent security of HCE for EMV payments, sought to put a positive face on the growing interest in the technology, in comments to financial analysts Thursday, following release of the company’s fourth quarter and year-end results. 

Among other things, HCE represents an endorsement of NFC by “all the main players of this ecosystem” for NFC, including Visa, MasterCard and Google, said Piou, who added that HCE would add momentum to the deployment of contactless point-of-sale terminals by merchants. In addition, he acknowledged that HCE enables easier development of applications for use with NFC phones, compared with secure elements. 

Some major telcos, including the Isis joint venture, have been using similar talking points, especially since Visa and MasterCard made their HCE announcements Feb. 19. 

But Piou, like the mobile operators, is taking a position on security that doesn’t quite match that of Visa and MasterCard or to jibe with the strict definition of HCE. Gemalto and the telcos are arguing that HCE is suited for such low-security applications as loyalty and couponing, not for open-loop payment. 

In this article: 

Words

3,500 

Among Topics Covered:

  • Gemalto CEO’s Olivier Piou’s contention that EMV tokens for HCE can't be secure in phone memory
  • Position of Visa and MasterCard on security of tokens and HCE
  • Piou: Decision on HCE security belongs to banks
  • Gemalto’s year-end revenue and profit report and multiyear goals
  • Review of hybrid approach to putting tokens on secure elements for cloud-based NFC payments
  • Oberthur’s take on HCE security
  • Isis’ view of HCE
  • Piou’s comments on Gemalto’s MCX contract and response to question about role vis-à-vis Paydiant 

Sources Quoted: 

Olivier Piou, CEO, Gemalto
Cédric Collomb, managing director, telecom, Oberthur Technologies
Scott Mulloy, CTO, Isis
Jorn Lambert, group executive, digital convergence, MasterCard 

Among companies and organizations mentioned:

Gemalto
Visa
MasterCard
Isis
Oberthur
MCX
Paydiant 

This is premium content from NFC Times.

Read Full Article 

© NFC Times and Forthwrite Media. NFC Times content cannot be copied or distributed without the express permission of the publisher.

HEADLINE NEWS

More Transit Authorities and Operators, Including Those in UK, to Support Google Pay

Nov 6 2019

NFC TIMES Exclusive – San Francisco Bay Area transit authority MTC has confirmed to NFC Times that it will support mobile payments with its closed-loop Clipper transit card, including with Google Pay, by the end of 2020.

NFC Wallets Make Up Growing Share of Contactless Payments on London Transit

NFC TIMES Exclusive – Use of NFC wallets continues to steadily increase as part of Transport for London’s landmark contactless payments service, with payments from NFC-enabled smartphones and smartwatches now accounting for 20% of all contactless payments, NFC Times has learned. 

Market Research Firm: Apple Pay Surpasses Starbucks App in Users in U.S.

NFC TIMES Exclusive Insight –Apple Pay, which launched its mobile payments service five years ago this week in the U.S., has so far failed to live up to expectations with the service, either in the U.S. or globally, in terms of users and transactions.

Cubic Strikes Deal with Google to Enable Closed-Loop Transit Payments in Google Pay

NFC TIMES Exclusive Insight – In a move that could enable more large transit agencies to offer NFC mobile payments with their closed-loop transit cards, U.S.-based Cubic Transportation Systems has signed an agreement with Google to integrate contactless transit cards with Google Pay. Among the agencies planning to support the service are those serving Google’s home base in Silicon Valley and the San Francisco Bay Area, as well as the Metropolitan Transportation Authority in New York. 

In-Depth: Persistent Consumer Security Fears about Mobile Payments Prove Difficult to Dislodge

NFC TIMES Exclusive Insight – Results of yet another survey has shown that a significant percentage of U.S. consumers continue to harbor security fears about using their smartphones for payments, a stubborn problem that has hindered growth of mobile payments from the beginning.

Mobile Suica Still Accounts for Disappointing Share of Suica Users and Transactions in Japan

NFC TIMES Exclusive – While Apple Pay next month will mark the 5th anniversary since its launch in the U.S., there is another contactless-mobile payments service that is three times as old as Apple Pay–Japan’s Osaifu-Keitai, or wallet phones, which this year turned 15. 

Rome Latest Transit System to Launch Open-Loop Fare Collection; also Enables Monthly Passes with EMV Cards

NFC TIMES Exclusive Insight – Rome has become the second major city in Italy–and one of a small but growing number of large cities globally–to enable riders to pay transit fares with EMV contactless credit, debit and prepaid cards and NFC devices.

Vivo Last of Major Chinese Smartphone Makers to Officially Launch NFC Pays Wallet

NFC TIMES Exclusive Insight – Vivo, China’s second largest smartphone maker, made it official this week, launching its NFC-enabled “vivo Pay” wallet, the last of the major Chinese phone OEMs to roll out NFC payments–though their use has been disappointing, at least for payments in stores.

In-Depth: Fit Pay’s Troubles Indicate Difficult Business Case for Provisioning to Wearables

Sep 19 2019

NFC TIMES Exclusive Insight –  Given the poor financial results of U.S.-based Fit Pay, it’s becoming clear that the business case for provisioning of payment cards to wearable devices remains difficult.

Analysis: Chase Pay Latest Bank Wallet to Shut Down; Why Did They Fail?

NFC TIMES Exclusive Insight – Plans disclosed this week by JPMorgan Chase to shut down its Chase Pay app for in-store purchases is yet another nail in the coffin–perhaps the final one–for bank wallets in the U.S. And the situation does not look much brighter for bank-issued wallets abroad.

Miami Latest U.S. City to Introduce Open-Loop Transit Payments

NFC TIMES Exclusive Insight Transit officials in Miami-Dade County, Fla. are the latest in the U.S. to introduce open-loop payments of fares with contactless credit and debit cards and bank card credentials on NFC wallets, launching the service yesterday on the city's relatively small metro network, with plans to expand to buses later.

UK Tram Riders Take to Tapping with NFC phones to Pay for Fares, According to Early Results

NFC TIMES Exclusive – Transport for Greater Manchester, which last month launched open-loop payments on its large Metrolink tram network, said Thursday that contactless credit and debit cards and NFC wallets accounted for a combined 170,000 rides during the first four weeks of the service.